一套针对 ChatGPT 账户、Codex 以及其中可能包含的敏感信息,防止未经授权访问的高级保护措施。
今天,我们推出高级账户安全功能,这是 ChatGPT 账户的一项全新可选设置,专为面临更高数字攻击风险的用户,以及希望获得最强账户保护的用户而设计。它整合了一系列增强的安全措施,有助于防范账户被盗用,同时让这些保护措施更易于在单一位置启用。一旦启用,高级账户安全功能同样能为 Codex 中的用户提供保护。
人们正越来越多地借助 AI 来探讨极为私密的问题,并处理日益高风险的日常工作。随着时间的推移,ChatGPT 账户可能承载敏感的个人与职业背景信息,并成为各类关联工具与工作流程的核心。对于某些人群,例如记者、民选官员、政治异见人士、研究人员以及特别注重安全的用户而言,其风险更高。
这项工作是我们更广泛的网络安全行动计划的一部分,旨在扩大对能够保护社区、关键系统及国家安全的技术的普及。我们希望用户拥有相应的控制权,以做出适合自身的安全与隐私选择。同时,我们也希望确保用户理解,高级账户安全功能带来的更强保护,也意味着用户在账户恢复方面需承担更大的责任。
高级账户安全功能的工作原理
高级账户安全功能整合了一系列控制措施,以强化登录保护、收紧账户恢复流程、减少因会话被入侵而带来的风险,并让用户更清晰地了解账户活动。用户可在其 ChatGPT 账户的“安全”设置中选择启用。该保护适用于通过该登录信息访问的 ChatGPT 和 Codex 账户。
更强的登录方式。高级账户安全功能要求使用通行密钥或物理安全密钥,同时禁用基于密码的登录,从而帮助最需要此类保护的用户将抗钓鱼登录设为默认方式。
更安全的账户恢复。如果用户的电子邮件账户或手机号码被攻破,攻击者可能会试图利用其中之一,通过电子邮件或短信恢复方式获取其 ChatGPT 账户的访问权限。为降低此风险,高级账户安全功能禁用了电子邮件和短信恢复,并要求使用更强的恢复方法:备份密钥、安全密钥和恢复密钥。由于账户恢复仅限于这些更安全的方法,OpenAI 支持团队将无法为已启用高级账户安全功能的用户提供账户恢复协助。
更短的会话时长与更清晰的会话管理。登录会话时长被缩短,以降低设备或活跃会话被攻破时的暴露窗口。当用户账户有登录活动时,用户还会收到提醒,并且可以查看和管理其已登录的各个设备上的活跃会话。
自动排除训练数据。处理特别敏感信息的用户可以选择不让这些对话用于模型训练。启用高级账户安全功能后,该偏好设置将自动生效:来自这些账户的对话将不会被用于训练我们的模型。
与 Yubico 合作,让抗钓鱼认证更易获取
使用物理安全密钥(例如 YubiKeys)是抵御钓鱼攻击最强大的手段之一。为了让用户更容易获得这种级别的保护,我们与硬件认证和账户保护领域的领导者 Yubico 合作,为我们的用户提供定制化最佳安全密钥套装的优惠价格。YubiKey C Nano 设计为可常驻笔记本电脑,用于简单、低摩擦的日常认证;而 YubiKey C NFC 则用于备份,并可在笔记本电脑和移动设备上使用。
我们作为高级账户安全功能的一部分推出此次合作,但该套装将面向所有符合条件的用户,在其安全设置中提供,以便更多人能够采用更强大、抗钓鱼的账户保护措施。用户也可以使用任何其他符合 FIDO 标准的安全密钥,或使用基于软件的密钥。
保护受信任的 Cyber 访问权限
我们持续扩展相关项目,让经过验证的防御者能够访问能力更强、权限更高的模型,同时我们必须确保这些防御者的账户受到我们最先进的安全保护。
自 2026 年 6 月 1 日起,访问我们最具网络能力且权限最高的模型的“可信网络访问”个人成员,将被要求启用高级账户安全。拥有可信访问权限的组织,也可以选择证明其单点登录流程中已包含抗钓鱼认证。
这是重要的一步,未来还有更多举措
OpenAI 正在成为 AI 的核心基础设施,让世界各地的人们以及大大小小的企业都能直接构建产品。ChatGPT 广泛的消费者触达能力,创造了一个强大的工作场所分发渠道——在这里,需求正迅速从基本的模型访问,转向能够重塑企业运营方式的智能系统。开发者通过利用我们的 API 来构建和扩展平台,而 Codex 正在改变开发者将创意转化为可用软件的方式。
随着 AI 日益融入我们的生活,确保用户拥有所需的控制权来保护自己的隐私和安全,比以往任何时候都更加重要。
隐私和安全是我们构建所有产品的基础,我们将持续投资于保护措施,随着时间的推移为用户提供更强的控制力和更坚固的保障。我们计划将这项工作扩展到更多受众,包括企业环境——在这些环境中,更强的账户安全同样至关重要。
希望获得额外保护的 OpenAI 用户,即日起即可注册高级账户安全。
- 2026
- ChatGPT
An advanced set of protections against unauthorized access to ChatGPT accounts, Codex, and the sensitive information they can contain.
Today, we’re introducing Advanced Account Security, a new opt-in setting for ChatGPT accounts, designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available. It brings together a set of heightened security measures that help safeguard against account takeover while making those protections easier to activate in one place. Once enrolled, Advanced Account Security protects users in Codex as well.
People are turning to AI for deeply personal questions and increasingly high-stakes work. Over time, a ChatGPT account can hold sensitive personal and professional context, and sit at the center of connected tools and workflows. For some people, like journalists, elected officials, political dissidents, researchers, and those who are especially security-conscious, the stakes are even higher.
This effort is part of our broader cybersecurity action plan to broaden access to the technologies that can help protect communities, critical systems, and our national security. We want users to have the controls to make the security and privacy choices that are right for them. At the same time, we want to ensure users understand that the increased protection of Advanced Account Security comes with an increased responsibility for account recovery.
How Advanced Account Security works
Advanced Account Security brings together a series of controls that strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. It’s available to opt into in the Security section of users’ ChatGPT accounts. Protection applies to both ChatGPT and Codex accounts that are accessed through that login.
Stronger sign-in methods. Advanced Account Security requires passkeys or physical security keys while disabling password-based login, helping make phishing-resistant sign-in the default for people who need it most.
More secure account recovery. If a user’s email account or phone number is compromised, an attacker may try to use one of them to gain access to their ChatGPT account via e-mail or SMS based recovery. To reduce this risk, Advanced Account Security disables email and SMS recovery and requires stronger recovery methods: backup passkeys, security keys, and recovery keys. Because account recovery is restricted to these more secure methods, OpenAI Support will not be able to assist with account recovery for users enrolled in Advanced Account Security.
Shorter sessions and clearer session management. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised. Users also receive alerts when there is a login to their account, and they can review and manage the active sessions across the various devices they’re signed into.
Automatic training exclusion. People working with especially sensitive information may opt not to have those conversations used for model training. With Advanced Account Security enabled, that preference is automatic: conversations from those accounts will not be used to train our models.
Making phishing-resistant authentication more accessible with Yubico
Using physical security keys, such as YubiKeys, is one of the strongest defenses against phishing. To make that level of protection easier to access, we have partnered with Yubico, a leader in hardware-based authentication and account protection, to offer our users preferred pricing on a customized bundle of best in class security keys. The YubiKey C Nano is designed to stay in your laptop for simple, low-friction daily authentication, and the YubiKey C NFC for backup, and use across laptops and mobile devices.
We’re launching this partnership as part of Advanced Account Security, but the bundle will be available to all eligible users in their security settings so more people can adopt stronger, phishing-resistant account protection. Users will also be able to use any other FIDO-compliant security key, or use software-based passkeys.
Protecting Trusted Access for Cyber
We continue to expand programs that give verified defenders access to more capable and permissive models, and we need to ensure that the accounts of those defenders are protected with our most advanced security protections.
Individual members of Trusted Access for Cyber accessing our most cyber capable and permissive models will be required to enable Advanced Account Security beginning June 1, 2026. Organizations with trusted access can, as an alternative, attest that they have phishing resistant authentication as part of their single sign-on workflow.
An important step, with more to come
OpenAI is becoming the core infrastructure for AI, making it possible for people around the world and businesses, big and small, to just build things. The broad consumer reach of ChatGPT creates a powerful distribution channel into the workplace, where demand is rapidly shifting from basic model access to intelligent systems that reshape how businesses operate. Developers build on and expand the platform by leveraging our APIs, and Codex is transforming how developers turn ideas into working software.
As AI becomes increasingly embedded in our lives, it is more important than ever to ensure that users have the controls they need to help protect their privacy and security.
Privacy and security are foundational to how we build all of our products and we’ll continue investing in protections that give people more control and stronger safeguards over time. We expect to extend this work to additional audiences, including enterprise environments, where stronger account security can matter just as much.
OpenAI users who want additional protection can enroll in Advanced Account Security starting today.